CyberRota Analysis
AI-GeneratedThe FluentBoards plugin for WordPress prior to version 1.95.3 is vulnerable due to inadequate authorization checks during board import operations, allowing authenticated users with member access to one board to access and copy stages and tasks from any other board. This could lead to unauthorized data exposure, including sensitive information such as titles, descriptions, and file attachments. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential data breaches.
Original NVD Description
The FluentBoards WordPress plugin before 1.95.3 does not verify that the items selected for a board import operation belong to a board the requesting user is authorized to access, allowing any authenticated user with member access to a single board to copy and read the stages and tasks (including titles, descriptions and file attachments) of any other board on the site.